Gootloader JS Dropper via wscript/cscript with Suspicious Child Process
Detects the execution of PowerShell or Command Prompt as child processes spawned by wscript.exe or cscript.exe, where the parent process command line indicates a JavaScript file being executed from the AppData or Temp directories. This behavior is highly characteristic of the Gootloader malware dropper, which leverages script engines to initiate subsequent malicious stages.
Splunk (SPL)

